Zubov-Net: Neural Methods for ROA Estimation
- Zubov-Net is a family of neural network methods that use Zubov theory to characterize regions of attraction (ROA) and safety domains in nonlinear dynamical systems.
- These approaches approximate Zubov-type PDEs, Hamilton–Jacobi–Bellman formulations, or Koopman fixed-point relations to enable controller synthesis, safety certification, and robustness regularization.
- Implementations range from two-stage neural controller designs and PINN-based safety verifications to operator learning techniques, yielding improved computational efficiency and accuracy.
Searching arXiv for the specified papers and closely related work on Zubov-Net. Zubov-Net is a label used in recent literature for a family of neural-network methods derived from Zubov theory for nonlinear dynamical systems. Across these works, the central object is a learned scalar function—variously denoted , , , or —whose sublevel geometry encodes a region of attraction (ROA), a safe domain of attraction, or a safe-stabilizable domain. The common technical motif is to approximate either a Zubov partial differential equation, a Zubov–Hamilton–Jacobi–Bellman equation, or a Zubov–Koopman fixed-point relation, and then use the learned function for controller synthesis, safety certification, robustness regularization, or ROA estimation (Li et al., 2 Jun 2025, Meng et al., 12 Nov 2025, Meng et al., 1 Apr 2026, Luo et al., 26 Sep 2025, Meng et al., 2023).
1. Terminological scope and problem setting
In the cited literature, “Zubov-Net” does not denote a single canonical architecture. Instead, it names several related constructions that all use Zubov-style characterizations of attraction domains. One line of work presents a two-stage framework that jointly synthesizes a neural state-feedback controller and a Lyapunov-like function for continuous-time systems, with direct ROA estimation and formal verification via an extended -CROWN verifier (Li et al., 2 Jun 2025). A second line treats “Zubov-Net” as a physics-informed neural network (PINN) for solving a Dirichlet-form Zubov PDE on a safe set boundary, so that the resulting function acts as a Lyapunov-barrier certificate (Meng et al., 12 Nov 2025). A third line extends the underlying PDE viewpoint to control-affine safe stabilization through a Zubov–HJB formulation whose viscosity solution yields a maximal control Lyapunov-barrier function (CLBF) (Meng et al., 1 Apr 2026). A fourth line uses the name for an adaptive stable learning framework for Neural ODE classifiers, where Zubov’s equation is reformulated as a consistency condition between prescribed regions of attraction (PRoAs) and true ROAs (Luo et al., 26 Sep 2025). A fifth, earlier line uses the term for a neural approximation of a Zubov–Koopman operator, learned from data and iterated to recover a Zubov solution for an unknown system (Meng et al., 2023).
The unifying task is the constructive approximation of a function whose level sets separate asymptotically stable behavior from instability or unsafety. In the classical autonomous setting, the exact ROA is identified with ; in the safety-constrained setting, the same structure is applied on a safe set with Dirichlet data on 0; in the control-affine setting, a maximization over admissible controls enters the PDE; and in the Neural ODE classification setting, each class equilibrium 1 is equipped with its own 2, whose sublevel set 3 is interpreted as a PRoA (Li et al., 2 Jun 2025, Meng et al., 12 Nov 2025, Meng et al., 1 Apr 2026, Luo et al., 26 Sep 2025).
2. Zubov-theoretic foundations
For continuous-time closed-loop dynamics
4
Zubov’s theorem characterizes the true ROA 5 by a continuously differentiable function 6 such that 7, 8 for 9, 0 as 1 or 2, and
3
A practical choice reported from Liu et al. is
4
which yields
5
Imposing 6 on 7 pins down the maximal ROA exactly as 8 (Li et al., 2 Jun 2025).
An equivalent autonomous formulation writes
9
with 0 and 1 on 2, where 3 is the domain of attraction. In that representation, 4 satisfies
5
and the ROA is exactly
6
This is the form used in the Zubov–Koopman lifting approach (Meng et al., 2023).
For safety-constrained autonomous systems, the literature introduces a Dirichlet-form Zubov PDE on the safe domain 7: 8 with boundary conditions
9
On a larger compact ROI 0, a positively rescaled modified problem is written as
1
where 2 (Meng et al., 12 Nov 2025).
For control-affine systems
3
the Zubov construction becomes an HJB-type PDE. If 4 is the value function defined by an infinite-horizon running cost 5, then 6 is the unique viscosity solution of
7
on the maximal safe-stabilizable domain 8, with 9 and 0 as 1 or 2. Under the Zubov transformation 3, one obtains
4
with 5 and 6 on 7 (Meng et al., 1 Apr 2026).
These formulations all preserve the same geometric principle: if the exact solution is obtained, then 8 is the maximal attractor-compatible domain. This suggests that the principal source of variation among Zubov-Net methods lies not in the underlying theorem, but in how the equation is approximated, sampled, regularized, and verified.
3. Two-stage neural controller synthesis and formal certification
The controller-synthesis variant parameterizes both a controller and a Zubov function by multilayer perceptrons. The controller is
9
where 0 is the known symmetric input limit and 1 is the equilibrium input. Each output coordinate is individually clamped to 2. The Zubov network is
3
with 4, ensuring 5. In practice, both 6 and 7 are standard fully connected layers with 8–9 hidden layers, width 0–1, tanh or ReLU hidden activations, and no batch normalization (Li et al., 2 Jun 2025).
Training proceeds in two stages. Stage 1 performs ROA estimation through a Zubov-guided curriculum. Every 2 steps, an UpdateDomain procedure expands the current domain 3. Two batches of 4 points are sampled by “Zubov-guided PGD”: interior points minimize 5, and exterior points minimize 6. Boundary points are sampled on 7. The composite loss includes 8, a Zubov PDE residual 9, a trajectory-consistency term 0, a controller term 1, and a boundary term 2, with weights learned via uncertainty weighting. The UpdateDomain procedure samples 3 points in 4 by PGD, simulates them for time 5 at step 6, records dimensionwise minima and maxima of convergent trajectories, forms a new box 7, and expands it by factor 8 (Li et al., 2 Jun 2025).
Stage 2 is a CEGIS refinement stage. It maintains a small buffer of counterexamples, attacks points in 9 via PGD to maximize
0
and then descends
1
plus a regularizer
2
Training stops when no new counterexamples appear. The stated intuition is that Stage 1 rapidly learns a roughly correct ROA by combining a physics-informed Zubov PDE loss with interior/exterior sampling and domain expansion, and Stage 2 removes local Lyapunov violations inside the estimated level set (Li et al., 2 Jun 2025).
Formal certification is based on an extension of 3-CROWN to continuous-time Jacobian products. To certify forward invariance of 4, the method uses a theorem requiring, for some 5, negativity of 6 on 7 and inward-pointing vector field behavior on 8. The verifier adds tight linear relaxations for 9 and 00 over input ranges 01, supports these in the bound-propagation engine, and replaces repeated bisection on 02 with an adaptive branch-and-bound scheme that updates 03 when a small counterexample is found, without re-verifying already certified subdomains (Li et al., 2 Jun 2025).
Reported quantitative results are explicit. ROA volume improvements over baselines are up to 04 on 05D systems, 06 on Cartpole (07D), 08 on PVTOL (09D), and 10 on a 11D quadrotor, with an overall estimate of up to 12 via Monte Carlo in 13D. On 14D benchmarks, dReal takes 15–16 s, whereas the extended CROWN verifier finishes each in 17–18 s, corresponding to a 19–20 speedup. The same source states that dReal often fails on Cartpole, while CROWN verifies it in approximately 21 s. It also notes that beyond 22D, Jacobian bound tightness remains a challenge; in 23D, forward invariance is verified only for a thin band, and empirical PGD or Monte Carlo is used for higher dimensions (Li et al., 2 Jun 2025).
4. Dirichlet Zubov-Net for safety and maximal CLBFs
The safety-oriented PINN formulation learns a function 24 on a compact ROI 25 using a fully connected feed-forward network with two hidden layers of width 26 and smooth activations such as tanh. Training uses 27 collocation points in 28, 29 boundary points on 30, and the origin. The losses are
31
32
and the total loss is
33
The reported hyperparameters are 34, 35, 36, with Latin-Hypercube sampling for collocation points, uniform sampling on 37, 38, 39, and Adam for 40 epochs (41k gradient steps) at learning rate 42 (Meng et al., 12 Nov 2025).
Verification in this framework targets both forward invariance and obstacle avoidance. For a sublevel set
43
the goal is to prove
44
LyZNet calls dReal or Z3 to prove the first-order formulas
45
and
46
for some small margin 47. Under the corresponding lemma, if 48 on 49 and 50, then 51 is forward-invariant and contains no unsafe points (Meng et al., 12 Nov 2025).
This safe-domain formulation is closely related to the later control-affine Zubov–HJB theory. There, the maximal safe-stabilizable domain is
52
under a compatibility assumption near the safe boundary. The transformed solution 53 is shown to be a continuous viscosity solution and a nonsmooth CLBF, with 54. Feedback is synthesized pointwise by
55
or equivalently in Zubov form using 56. The associated “Zubov-Net” implementation recipe minimizes interior PDE residual, Dirichlet boundary losses, optional inequality penalties, and a gradient regularizer, using a fully connected MLP with tanh or softplus and either a sigmoid output or a clamped parameterization to keep 57 (Meng et al., 1 Apr 2026).
The empirical benchmark reported for the Dirichlet safe-domain PINN is the reversed Van der Pol system with two circular obstacles, where the learned and verified level set recovered roughly 58 of the true area, while a quadratic CLF approach captured 59. Training times are reported as 60–61 minutes and formal verification as 62–63 minutes per example. The same source identifies two limitations: the need to choose a proper indicator 64 such that 65 at 66 and 67 diverges, and the fact that formal verification can be conservative and does not scale beyond 68–69 (Meng et al., 12 Nov 2025).
5. Zubov-Net for Neural ODE robustness and prescribed attraction geometry
A distinct use of the name appears in Neural ODE classification, where Zubov-Net is an “adaptive stable learning framework” that seeks to reconcile robustness and accuracy by actively controlling basin geometry. The system is
70
with equilibrium set 71, one equilibrium per class. The true ROA of equilibrium 72 is
73
and the PRoA is defined by a learnable Lyapunov function 74 through
75
The stated interpretation is that 76 is the current guess of 77 (Luo et al., 26 Sep 2025).
The central reformulation is a consistency loss derived from Zubov’s equation. If 78, 79 on 80, and
81
for all 82, with 83 for 84, then 85. The paper turns this into
86
and globally enforces
87
It states that 88 if and only if each PRoA exactly satisfies Zubov’s PDE and hence aligns with the true 89 (Luo et al., 26 Sep 2025).
Two additional losses control class assignment and basin separation. The classification term uses the Lyapunov-value vector
90
and the normalized inverse-value map
91
with
92
The separation term samples boundary points 93 and penalizes
94
where 95 and 96. The total objective combines classification, a term 97, consistency, and separation (Luo et al., 26 Sep 2025).
A notable architectural contribution is the input-attention convex neural network for the pre-Lyapunov potential
98
The 99-layer IACNN uses softmax attention over 00 and previous features 01, with elementwise nonnegative 02 and convex non-decreasing 03, so that 04 is convex in 05. The paper states that the softmax attention mechanism focuses on equilibrium-relevant features and also serves as weight normalization to maintain training stability in deep architectures (Luo et al., 26 Sep 2025).
The parallel boundary sampling algorithm updates radial lengths 06 along directions 07 by sign feedback until the target level 08 is reached. All updates are performed in parallel, and the argument relies on radial monotonicity induced by strong convexity. The stated theoretical guarantees are: 09 if and only if 10; 11 implies 12 for 13; and if 14 and 15, then the entire trajectory 16 for 17 stays in 18 (Luo et al., 26 Sep 2025).
The empirical results are reported on SVHN, CIFAR-10, and CIFAR-100. For noise robustness, average over eight corruptions plus clean is 19 on SVHN versus 20 for the next best SODEF, 21 on CIFAR-10 versus 22, and 23 on CIFAR-100 versus 24. For white-box adversarial robustness, averaged over FGSM, PGD, BIM, APGD, and Jitter at 25, the results are 26 on SVHN versus 27 for FxTS-Net, 28 on CIFAR-10 versus 29, and 30 on CIFAR-100 versus 31. Clean accuracy remains on par or better than baselines, with CIFAR-10 reported as 32 versus 33 for a standard Neural ODE. The ablation claims are explicit: removing 34 sharply degrades adversarial robustness, removing 35 degrades noise robustness, and the full tripartite loss gives the best overall trade-off (Luo et al., 26 Sep 2025).
6. Zubov–Koopman lifting and data-driven ROA learning
The Zubov–Koopman line addresses unknown autonomous systems from data. For
36
with asymptotically stable equilibrium at 37, the one-step Zubov–Koopman operator is defined for any bounded continuous 38 by
39
where 40 is the flow and 41 is a positive-definite weight. The family 42 is a strongly continuous linear semigroup on 43, with infinitesimal generator
44
The Zubov solution 45, extended by 46 outside the ROA, is the unique bounded fixed point of each one-step map: 47 This converts ROA estimation into operator learning (Meng et al., 2023).
The neural parameterization chooses feature functions
48
and approximates
49
with 50. A decoder row vector 51 then yields
52
Under power iteration, the full ANN is
53
which the source calls the “Zubov-Net.” Typical choices include sinusoidal, Fourier, monomial, or small-MLP features; 54 may be unconstrained or regularized; and 55 may use softplus to enforce 56 (Meng et al., 2023).
Training combines an EDMD-style operator-fit term and a PDE residual. Given pairs 57 and weights 58, the losses are
59
and
60
with total loss
61
The recovery step uses
62
and under a spectral gap assumption on 63, 64 as 65. The final Lyapunov candidate is 66 (Meng et al., 2023).
The paper states several convergence ingredients: the semigroup property 67; the improper-integral formula
68
yielding a bounded continuous function; uniqueness of the bounded viscosity solution of the Zubov PDE by a comparison principle; finite-rank approximation of 69 by projection onto leading eigenfunctions; EDMD strong convergence with sufficiently rich dictionary and enough data; and convergence of 70 to the fixed-point projector when the learned 71 has dominant eigenvalue 72 and spectral gap (Meng et al., 2023).
The numerical examples include reversed Van der Pol, a polynomial stiff system, a 73D nonlinear system, and a two-machine power system with a sine nonlinearity. The common setup uses a region 74 containing the ROA, 75, 76 or a minor variant, a small MLP dictionary with two hidden layers of 77 units and ReLU or smooth activations, batch size 78–79, and 80–81 epochs of joint EDMD plus PDE loss followed by 82–83 power iterations. In the reversed Van der Pol example, the Hausdorff error is approximately 84. The report states that all examples converge in under 85 power iterations and are finally checked by verifying 86 on a dense grid in 87 (Meng et al., 2023).
7. Limitations, misconceptions, and research directions
A common misconception is that Zubov-Net denotes a single fixed neural architecture. The literature instead supports a broader interpretation: the term refers to several neural approximators of Zubov-type objects—PDE solutions, viscosity solutions, Lyapunov-barrier functions, or operator fixed points—adapted to different tasks such as controller synthesis, safety certification, Neural ODE robustness, or operator learning (Li et al., 2 Jun 2025, Meng et al., 12 Nov 2025, Luo et al., 26 Sep 2025, Meng et al., 2023).
Another misconception is that all Zubov-Net methods are verification-complete. The sources distinguish sharply between approximate learning and formal certification. The controller-synthesis framework extends 88-CROWN and reports substantial speedups over dReal, but also states that Jacobian bound tightness remains a challenge beyond 89D and that empirical PGD or Monte Carlo is used in higher dimensions (Li et al., 2 Jun 2025). The safe-domain PINN framework uses SMT solvers through LyZNet, yet explicitly notes that formal verification is conservative and does not scale beyond 90–91 (Meng et al., 12 Nov 2025). The Neural ODE robustness framework proves consistency, non-overlap, and finite-time containment under the exact-loss condition 92, but its empirical claims concern robustness metrics rather than formal reachability certificates (Luo et al., 26 Sep 2025). The Koopman-lifting approach provides strong convergence statements under regularity, richness, and spectral assumptions, but its final verification step is described as dense-grid checking rather than theorem-proving (Meng et al., 2023).
The main technical bottlenecks are also consistent across the literature. High-dimensional verification is limited by bound tightness for Jacobian terms in continuous-time systems (Li et al., 2 Jun 2025). Boundary-layer resolution may require many collocation points in very high dimensions (Meng et al., 12 Nov 2025). Safe-domain formulations require a proper indicator 93 whose blow-up behavior is suitable near the boundary (Meng et al., 12 Nov 2025). Control-affine formulations rely on compatibility assumptions near the safe boundary and on viscosity-solution machinery, which suggests that numerical realization is naturally more delicate than the autonomous case (Meng et al., 1 Apr 2026).
Taken together, these works position Zubov-Net not as a single algorithm, but as a research program centered on constructive approximations of maximal attraction-compatible functions. The consistent structural claim is that, when the relevant Zubov-type equation is solved accurately enough and the resulting certificate is formally or empirically validated, the sublevel set 94 provides a non-conservative under-approximation—or in the ideal exact case, the exact characterization—of the underlying ROA, safe domain of attraction, or safe-stabilizable region (Li et al., 2 Jun 2025, Meng et al., 12 Nov 2025, Meng et al., 1 Apr 2026).